Running Windows 7, 8 or 10? You need to patch these critical vulnerabilities now

(Image credit: Microsoft)

Microsoft has issued patches for a pair of critical vulnerabilities which are ‘wormable’ and present in all recent versions of Windows, with the software giant advising that you should download these as soon as possible due to the risk involved here.

The vulnerabilities in Remote Desktop Services, which allow for remote code execution – meaning the attacker can pretty much pull off anything, such as installing malware or plundering your data – are codenamed CVE-2019-1181 and CVE-2019-1182.

They affect Windows 7 SP1, Windows 8.1, and all supported versions of Windows 10 (as well as Windows Server 2008 R2 SP1, Windows Server 2012/R2, and Windows 10 server versions).

The fact that they are wormable means that malware built to exploit these security flaws could spread from computer to computer without any user interaction, assuming those PCs are vulnerable of course. And naturally, that’s the most worrying kind of malware, where you don’t have to be tricked into clicking some dodgy link or downloading something with a payload inside.

Microsoft stressed: “It is important that affected systems are patched as quickly as possible because of the elevated risks associated with wormable vulnerabilities like these.”

You can check here to download the security patches manually, but if you have automatic updates switched on, your OS will grab the relevant fixes for you (or you could head to Windows Update, and check for new updates).

Remotely dangerous

If all this is ringing a bell or three, that’s probably because we recently witnessed BlueKeep emerging, another wormable vulnerability in Remote Desktop Services, although that particular flaw didn’t affect Windows 8 or Windows 10.

This time around, all versions of Windows are under threat – except for Windows XP – so you should patch up pronto (and if you’re still on XP, well, that’s a far more worrying state of security affairs in itself).

Microsoft does observe, however, that there is no evidence the vulnerabilities were known to any third-parties before this announcement.

Of course, hackers may have previously found the flaws without Microsoft realizing, and at any rate, now the vulnerabilities have been publicly detailed, there’s an obvious danger of a weaponized exploit turning up – and possibly in quite a rapid timeframe.

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Windows
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
girl using laptop hoping for good luck with her fingers crossed
Windows 11 24H2 seems to be a massive fail – so Microsoft apparently working on 25H2 fills me with hope... and fear
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
Using Zipped files and folders in Windows 11
Windows 11 should soon be faster at extracting files from compressed ZIPs – and it’s about time, frankly
Xbox Wireless Controller
Microsoft is adding a powerful new feature for using Xbox controllers with Windows 11
Latest in News
Buzz Lightyear Space Ranger Spin Rennovations
Disney’s giving a classic Buzz Lightyear ride a tech overhaul – here's everything you need to know
Hisense U8 series TV on wall in living room
Hisense announces 2025 mini-LED TV lineup, with screen sizes up to 100 inches – and a surprising smart TV switch
Nintendo Music teaser art
Nintendo Music expands its library with songs from Kirby and the Forgotten Land and Tetris
Opera AI Tabs
Opera's new AI feature brings order to your browser tab chaos
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead